You’re Not Stuck – You’re Normalizing Risk

Hillstrong Group Security ·

Author: Roger Hill

What Happens After the Duct Tape Phase in OT Security

Temporary fixes and improvisation helped early OT programs survive. But what happens when those unowned decisions become a material exposure?

Start Where the Board Feels It — Governance, Not Controls

In every audit or resilience review, we ask the same foundational questions:

  • Who owns the security controls that keep your plants running?
  • Are those controls documented, validated, and recoverable across your critical sites?
  • Can you prove that what’s been deployed matches what’s been approved?

For too many industrial organizations, the answer is: it depends.

And that’s the governance gap — not in policy, but in practice.

The Quiet Risk: Drifted Controls, Unowned Decisions

The early phase of OT cybersecurity progress was shaped by field ingenuity. Plant teams implemented jump boxes. Integrators segmented networks. Vendor access was firewalled using whatever was available.

It worked. It prevented outages. It bought time.

But today, those tactical wins — untracked, unaudited, and often undocumented — have become embedded in production environments. And they now present a different kind of threat:

They represent ungoverned risk.

No single person owns them. No board has visibility into them. And no audit framework — until something breaks — holds them accountable.

Why This Now Matters at the Top

Boards and CFOs aren’t asking whether your segmentation policy is mature. They’re asking:

  • If we suffer a ransomware incident, can we demonstrate control integrity?
  • If we report resilience posture, can we defend it under scrutiny?
  • If insurance declines coverage, what did we fail to disclose?

The problem isn’t that OT teams were scrappy. The problem is that leadership never went back to replace improvisation with institutional governance.

And that is no longer a technical oversight. It’s a strategic liability.

Executive Example: When “Working” Isn’t Defensible

We recently worked with a manufacturer that had avoided major cyber incidents for years. Their board was confident. Their audits were clean.

Then a cloud-based identity outage disabled access to OT systems in two sites. The business impact was modest — but the investor reaction wasn’t.

  • They couldn’t confirm which controls failed
  • They couldn’t prove which sites had fallback
  • They couldn’t verify what had been recovered manually

The technology hadn’t failed. The documentation had. And the confidence in the company’s risk posture — from board to regulator to market — suffered.

This is the moment many organizations are walking toward without realizing it.

Strategic Response: Reasserting Control Without Slowing Execution

Boards shouldn’t be looking for perfection — but they do need governance. Here’s how mature OT security leaders are reasserting control:

  1. Control Inventory Validation Identify every site with improvised or undocumented controls still in use. List them. Track them. Tie them to a system of record.
  2. Governance by Tiered Criticality Not every plant needs the same posture. But every high-revenue, high-safety, or board-visible facility must have governance-level maturity — not tactical improvisation.
  3. Handoff to Business Ownership Elevate ownership of these controls. They must no longer be “maintained by engineering” or “tracked in a spreadsheet.” They must become governed business assets.
  4. Time-Bound Retirement of Improvisation Duct tape was fine. But it needs an expiration date. Set a 6–12 month horizon to either retire or reinforce every ad-hoc security mechanism with approved architecture.

Resilience Without Governance Is a Mirage

What scrappy execution gave us was time. What we do with that time determines whether we’re building resilience — or just surviving.

If you’re a board member, ask the CISO:

“How much of our plant-level risk posture is still built on unaudited fixes?”

If you’re a CISO, ask the COO:

“How many of our controls could we defend, document, and recover under pressure?”

And if you don’t like the answer, you’re not behind – you’re right on time. But you need to act now.

And if you’ve already made that leap – tell me how. Let’s show others what post-duct-tape OT security really looks like.

Thanks for reading! Feel free to reach out here on the website or on LinkedIn: Roger Hill

Want this as a playbook?

Every guide we publish has a companion eBook with templates you can use today.